{"_id":"@dizitart/bcup2kdbx","_rev":"3-8bfaec4f2237aad8bf23fb5be4bc3990","name":"@dizitart/bcup2kdbx","dist-tags":{"latest":"1.0.0"},"versions":{"0.0.0":{"name":"@dizitart/bcup2kdbx","version":"0.0.0","keywords":["buttercup","bcup","kdbx","kdbx4","keepass","keepassxc","password-manager","vault","migration","converter","cli"],"author":{"name":"Dizitart"},"license":"Apache-2.0","_id":"@dizitart/bcup2kdbx@0.0.0","maintainers":[{"name":"anidotnet","email":"anidotnet@gmail.com"}],"homepage":"https://github.com/dizitart/bcup2kdbx#readme","bugs":{"url":"https://github.com/dizitart/bcup2kdbx/issues"},"bin":{"bcup2kdbx":"convert.js"},"dist":{"shasum":"7397b067dea201d121c554826262f5c7dcb538fb","tarball":"https://registry.npmjs.org/@dizitart/bcup2kdbx/-/bcup2kdbx-0.0.0.tgz","fileCount":7,"integrity":"sha512-fS1qdEK4vM6hvldzsaCm+cRrPLh4EhmXjKMAZCp770OWqaylwqKC0VgDEgkqb46z9oy2bFffrAm7fJb3yLYOCQ==","signatures":[{"sig":"MEYCIQC1W+Cz0xZGLvyJSVqE4Z2nBMbOZkIrs5VAGTV4jAOH+QIhAL0LpPUTdWpnwa0PDxGda8gYqju2vY12SR62RReu3vHL","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":41488},"main":"./lib.js","type":"module","engines":{"node":">=20.0.0"},"exports":{".":"./lib.js"},"gitHead":"5d721a6e8ad07df7c51d5a35d221e0db2bf5b4bf","scripts":{"test":"node test.js"},"_npmUser":{"name":"anidotnet","email":"anidotnet@gmail.com"},"overrides":{"uuid":"^11.1.1"},"repository":{"url":"git+https://github.com/dizitart/bcup2kdbx.git","type":"git"},"_npmVersion":"11.6.0","description":"Convert a Buttercup vault (.bcup) into a KDBX 4 (KeePass) database, preserving groups, fields, attachments and trash","directories":{},"_nodeVersion":"24.8.0","dependencies":{"kdbxweb":"^2.1.1","buttercup":"^7.7.1","hash-wasm":"^4.12.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/bcup2kdbx_0.0.0_1788097920877_0.5471451101182812","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Placeholder used to bootstrap trusted publishing"},"1.0.0":{"name":"@dizitart/bcup2kdbx","version":"1.0.0","keywords":["buttercup","bcup","kdbx","kdbx4","keepass","keepassxc","password-manager","vault","migration","converter","cli"],"author":{"name":"Dizitart"},"license":"Apache-2.0","_id":"@dizitart/bcup2kdbx@1.0.0","maintainers":[{"name":"anidotnet","email":"anidotnet@gmail.com"}],"homepage":"https://github.com/dizitart/bcup2kdbx#readme","bugs":{"url":"https://github.com/dizitart/bcup2kdbx/issues"},"bin":{"bcup2kdbx":"convert.js"},"dist":{"shasum":"7e1261480065af87cd9d8890447be900509cd1a6","tarball":"https://registry.npmjs.org/@dizitart/bcup2kdbx/-/bcup2kdbx-1.0.0.tgz","fileCount":7,"integrity":"sha512-ZUvhzuDcy+LhYLIRFrbv/nFeT9HXhLaDb5h/M07xqpWyTj62mXxsF7cnJggZ7ILMAEL0E0p+qa7PbTSWP/ggKw==","signatures":[{"sig":"MEUCIQD6obM8fAOvBzVaHNmyO5hEYdiExM8pYrKcwtuNx79VSgIgNmX8GJJcbxvCdSHKsuh8ByZUIkbF1pBEIZ8t2l/Ca5k=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@dizitart%2fbcup2kdbx@1.0.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":41488},"main":"./lib.js","type":"module","engines":{"node":">=20.0.0"},"exports":{".":"./lib.js"},"gitHead":"5d721a6e8ad07df7c51d5a35d221e0db2bf5b4bf","scripts":{"test":"node test.js"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:843feefa-ef3b-4ac1-9f25-b39bed2c0fa1"}},"overrides":{"uuid":"^11.1.1"},"repository":{"url":"git+https://github.com/dizitart/bcup2kdbx.git","type":"git"},"_npmVersion":"12.0.2","description":"Convert a Buttercup vault (.bcup) into a KDBX 4 (KeePass) database, preserving groups, fields, attachments and trash","directories":{},"_nodeVersion":"22.23.2","dependencies":{"kdbxweb":"^2.1.1","buttercup":"^7.7.1","hash-wasm":"^4.12.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/bcup2kdbx_1.0.0_1788098177877_0.7232127974562552","host":"s3://npm-registry-packages-npm-production"}}},"time":{"created":"2026-08-30T13:52:00.727Z","modified":"2026-08-30T14:14:11.037Z","0.0.0":"2026-08-30T13:52:01.027Z","1.0.0":"2026-08-30T13:56:18.033Z"},"bugs":{"url":"https://github.com/dizitart/bcup2kdbx/issues"},"author":{"name":"Dizitart"},"license":"Apache-2.0","homepage":"https://github.com/dizitart/bcup2kdbx#readme","keywords":["buttercup","bcup","kdbx","kdbx4","keepass","keepassxc","password-manager","vault","migration","converter","cli"],"repository":{"url":"git+https://github.com/dizitart/bcup2kdbx.git","type":"git"},"description":"Convert a Buttercup vault (.bcup) into a KDBX 4 (KeePass) database, preserving groups, fields, attachments and trash","maintainers":[{"name":"anidotnet","email":"anidotnet@gmail.com"}],"readme":"# bcup2kdbx\n\n[![CI](https://github.com/dizitart/bcup2kdbx/actions/workflows/ci.yml/badge.svg)](https://github.com/dizitart/bcup2kdbx/actions/workflows/ci.yml)\n[![npm](https://img.shields.io/npm/v/@dizitart/bcup2kdbx.svg)](https://www.npmjs.com/package/@dizitart/bcup2kdbx)\n[![node](https://img.shields.io/node/v/@dizitart/bcup2kdbx.svg)](https://nodejs.org)\n[![licence](https://img.shields.io/badge/licence-Apache--2.0-blue.svg)](LICENSE)\n\nConvert a [Buttercup](https://buttercup.pw) vault (`.bcup`) into a **KDBX 4** database you\ncan open in KeePassXC, KeePass 2, KeeWeb, Strongbox, or anything else that reads KeePass\nfiles.\n\nGroups, custom fields, attachments, tags, OTP secrets and the trash all come across. The\ntool re-reads the file it just wrote and proves nothing was dropped before it exits.\n\n```\n$ bcup2kdbx ~/Buttercup.bcup ~/Buttercup.kdbx\nMaster password for /Users/you/Buttercup.bcup:\nNew password for /Users/you/Buttercup.kdbx:\nConfirm password:\nUnlocking vault...\nRead 14 group(s), 231 entry/entries.\nConverting...\nWrote /Users/you/Buttercup.kdbx (271104 bytes, KDBX 4, Argon2id).\nVerifying...\nVerified: every group, property value and attachment round-tripped.\n```\n\n## Install\n\n```bash\nnpm install -g @dizitart/bcup2kdbx\n```\n\nOr run it once without installing:\n\n```bash\nnpx @dizitart/bcup2kdbx vault.bcup vault.kdbx\n```\n\nRequires Node 20 or later.\n\n## Use\n\n```bash\nbcup2kdbx <input.bcup> <output.kdbx> [options]\n```\n\nIt prompts for the vault's master password, then twice for the password that will protect\nthe new KDBX file. **Passwords are never read from command-line arguments or environment\nvariables**, so they cannot leak into your shell history or into `ps` output.\n\n| Option | Effect |\n| --- | --- |\n| `--name <text>` | Database name stored inside the KDBX file (default: the input filename) |\n| `--out-keyfile <path>` | Additionally protect the KDBX file with a key file |\n| `--no-verify` | Skip the post-write verification pass |\n\nExit codes: `0` success, `1` error, `2` verification found missing data.\n\n### Getting a `.bcup` file\n\nIn the Buttercup desktop app the vault file on disk *is* the `.bcup` — for a local vault\nit is the file you chose when you created it. For a cloud vault (Dropbox, Google Drive,\nWebDAV), download the `.bcup` from that service first.\n\n### After converting\n\nOpen the result in your KeePass client and spot-check a handful of entries before you\ndelete anything. The verification pass proves the data is in the file; it cannot prove\nyour particular client displays it the way you expect.\n\n## What gets preserved\n\n| Buttercup | KDBX 4 |\n| --- | --- |\n| Nested group tree | Nested group tree, same shape |\n| `title` / `username` / `password` / `url` / `note` | `Title` / `UserName` / `Password` / `URL` / `Notes` |\n| Any other property | Custom string field under its original name |\n| Anything in the `Password` slot, anything typed `password` or `otp`, and `privateKey` | Stored as a **protected** value |\n| A property typed `otp` (an `otpauth://` URI) | The `otp` field, which KeePassXC reads natively to generate TOTP codes |\n| Entry attachments | KDBX binaries, original filename and bytes |\n| Entry tags | Entry tags |\n| Entry type (`login`, `website`, `credit_card`, `note`, `ssh_key`) | An extra tag, plus `BC_ENTRY_FACADE_TYPE` in entry CustomData |\n| All Buttercup entry / group / vault attributes | CustomData on the entry / group / metadata |\n| Trash | Recycle Bin |\n\nCredit-card entries follow Buttercup's own layout: the card holder is `username` and the\ncard number is `password`, so they land in `UserName` and `Password`.\n\nIf a custom field collides with a slot already taken — an entry with both `title` and\n`Title`, say — the canonical lower-case property wins the standard KDBX field and the other\nis kept alongside it as `Title (2)`. Nothing is silently dropped.\n\n### Two things that are not carried over verbatim\n\n**Entry history.** Buttercup stores a field-level changelog, not entry snapshots.\nReconstructing KDBX history entries from it would fabricate \"previous versions\" that never\nexisted, so only current values are written.\n\n**Entry timestamps.** Buttercup stores none of its own. Creation and modification times are\nderived from the earliest and latest entry in that changelog — the best answer available,\nbut derived rather than recorded.\n\n### Tabs and carriage returns\n\nIf a field value contains a tab or a `\\r\\n` line ending, the converter prints a note during\nverification. The characters **are written to the KDBX file intact** — kdbxweb's serialiser\nemits them verbatim — but kdbxweb's own XML reader drops tabs when it loads the file back,\nso the verification pass can only match those values after normalising. Whether a tab\nsurvives into your KeePass client depends on that client's XML parser; a spec-compliant\nparser keeps tabs in element content and collapses `\\r\\n` to `\\n`.\n\nThis affects display only. Nothing is dropped from the file that is written.\n\n## How it works\n\nReading is done by [`buttercup`](https://www.npmjs.com/package/buttercup) — Buttercup's own\nvault stack, so decryption, format handling and attachment decryption are exactly what the\nButtercup app does. Writing is [`kdbxweb`](https://www.npmjs.com/package/kdbxweb). Neither\nformat is parsed or serialised by hand anywhere in this repository.\n\n`kdbxweb` ships no Argon2 implementation, so [`hash-wasm`](https://www.npmjs.com/package/hash-wasm)\nsupplies one. Output is KDBX 4 with **Argon2id** key derivation.\n\nEverything runs locally. There is no network access at runtime and no telemetry.\n\n### Use as a library\n\n```js\nimport { openVault, vaultToKdbx } from \"@dizitart/bcup2kdbx\";\nimport { writeFileSync } from \"node:fs\";\n\nconst source = await openVault(\"vault.bcup\", vaultPassword);\nconst db = await vaultToKdbx(source, newPassword, { name: \"My Vault\" });\nwriteFileSync(\"vault.kdbx\", Buffer.from(await db.save()));\nawait source.lock();\n```\n\n`vaultToKdbx` returns a `kdbxweb` `Kdbx` instance, so you can modify it further before\nsaving.\n\n## Verification\n\nAfter writing, the converter reloads the file from disk and checks that every group, every\nproperty value and every attachment from the source vault is present in the output. If\nanything is missing it lists what and exits `2`.\n\n`npm test` runs an end-to-end self-check against a synthetic vault covering nested groups,\nall five entry types, OTP fields, attachments, field-name collisions and trashed entries.\n\n## Contributing\n\nSee [CONTRIBUTING.md](CONTRIBUTING.md). Bug reports are welcome — please build a synthetic\nvault to demonstrate the problem rather than sending anything real.\n\nSecurity problems go through [private reporting](SECURITY.md), never a public issue.\n\n## Licence\n\n[Apache License 2.0](LICENSE). Copyright 2026 Dizitart.\n","readmeFilename":"README.md"}